Remix.run Logo
redleader55 2 days ago

Again, if you need to revoke a certificate, it means something terrible happened - someone compromised your server and your website has a good chance to be impersonated by 3rd parties. In all the other cases, you just let the old cert expire. You likely don't want people finding out about the revocation 12-24 hours later.

robertlagrant a day ago | parent [-]

OCSP-stapling seemed to be fine with 24-48 hour client-side caching, though.